CVE-2024-48884 Information

Description

A improper limitation of a pathname to a restricted directory (‘path traversal’) in Fortinet FortiManager versions 7.6.0 through 7.6.1 7.4.1 through 7.4.3 FortiOS versions 7.6.0 7.4.0 through 7.4.4 7.2.5 through 7.2.9 7.0.0 through 7.0.15 6.4.0 through 6.4.15 FortiProxy 7.4.0 through 7.4.5 7.2.0 through 7.2.11 7.0.0 through 7.0.18 2.0.0 through 2.0.14 1.2.0 through 1.2.13 1.1.0 through 1.1.6 1.0.0 through 1.0.7 FortiManager Cloud versions 7.4.1 through 7.4.3 FortiRecorder versions 7.2.0 through 7.2.1 7.0.0 through 7.0.4 FortiVoice versions 7.0.0 through 7.0.4 6.4.0 through 6.4.9 6.0.0 through 6.0.12 FortiWeb 7.6.0 7.4.0 through 7.4.4 7.2.0 through 7.2.10 7.0.0 through 7.0.10 6.4.0 through 6.4.3 allows attacker to trigger an escalation of privilege via specially crafted packets.

Reference

https://fortiguard.fortinet.com/psirt/FG-IR-24-259

Share on: